System and method for providing trace information data reduction

ABSTRACT

The present invention is a system, method, and computer readable medium for representing program event trace information in a way which is very compact and efficient, and yet supports a wide variety of queries regarding system performance. The tracing and reduction of the present invention may be dynamic, in which case information is obtained and added to the trace representation in real-time. Alternately, the tracing and reduction may be static, in which case a trace text file or binary file is obtained from a trace buffer, and the reduction takes place using the trace file as input. The trace information, whether obtained statically or dynamically, is represented as a tree of events. The present invention may be used to present many types of trace information in a compact manner which supports performance queries. For example, the tree structure of the present invention may reflect the call stacks observed during a program&#39;s execution, and statistics regarding the time spent in the various routines and call stacks may be stored at each node of the tree. The tree structure may be used to store performance information regarding Java bytecodes executed, memory allocated, or other types of performance information. The trace information is presented in a manner which is compact and efficient, and may be used to quickly and easily answer a variety of performance queries. Further, a system may be traced for long periods of time without losing useful performance information due to a limited buffer space.

FIELD OF THE INVENTION

The present invention relates to information processing systems and,more particularly, to software tools and methods for monitoring,modeling, and enhancing system performance.

BACKGROUND OF THE INVENTION

To enhance system performance, it is helpful to know which moduleswithin a system are responsible, either directly or indirectly, for themost significant consumption of the most critical system resources.Effective systems management depends on knowing how and when systemresources are being used. Similarly, a developer hoping to improvesystem performance should focus his or her efforts on improving theresource consumption characteristics of the modules which consume thelargest amount of critical resources.

Performance tools are used to examine the system in order to determineresource consumption as programs execute. For example, a performancetool may identify the most frequently executed modules and instructionsin a system, or may identify those modules which allocate the largestamount of memory or perform the most I/O requests. Performance tools maybe implemented in hardware or software. Hardware performance tools areusually built into the system. Software performance tools may be builtinto the system or added at a later point in time.

Performance tools implemented in software are especially useful insystems, such as personal computer systems, that do not contain many, ifany, built-in hardware performance tools.

One type of prior art software performance tool, referred to as a tracetool, keeps track of particular sequences of instructions by loggingcertain events as they occur. For example, a trace tool may log everyentry into and every exit from a module, subroutine, method, function,or system component. Alternately, a trace tool may log the requester andamount of memory allocated for each memory allocation request.Typically, a time stamped record is produced for each such event. Pairsof records similar to entry-exit records are also used to traceexecution of arbitrary code segments, to record acquiring and releasinglocks, starting and completing I/O or data transmission, and for manyother events of interest.

A developer or systems manager is typically presented with a "trace" ofthe results. The trace is often stored as a text file, such as theexample trace, showing entries into and exits from modules, depicted inFIG. 1. The trace in FIG. 1 shows that module "C" is the first moduleentered. Module "C" calls module "A," module "A" calls module "B," andso on.

FIG. 1 depicts a very small piece of a larger trace. Typically, tracesare many millions of entries long. Because loops are common in programs,trace files often contain patterns of events repeated many times. Thetypical text file trace output may be read by a developer or systemsmanager, and is adequate for gaining an understanding of very small timeperiods within the trace. However, a text file trace output is toocumbersome to use when attempting to analyze large scale behavior andpatterns contained in a trace. Furthermore, the size of the trace islimited by the buffer space allocated to store the trace. Thus, a systemmay be traced for a limited, and often very short, period of time.

Consequently, it would be desirable to have a system and method forproviding trace information to a developer or systems manager in acompact and highly efficient manner. It would also be desirable toprovide the trace information in such a way as to facilitateunderstanding of the system's operation, and highlight opportunities forperformance improvement. It would be further desirable to allow a systemto be traced for longer periods of time without losing usefulperformance and behavioral information due to limited buffer space.

SUMMARY OF THE INVENTION

Accordingly, the present invention is directed to a system, method, andcomputer readable medium for representing program event traceinformation in a way which is very compact and efficient, and yetsupports a wide variety of queries regarding system performance. Thetracing and reduction of the present invention may be dynamic, in whichcase information is obtained in real-time, as each event occurs, and isautomatically reduced and added to the trace representation.Alternately, the tracing and reduction of the present invention may bestatic, in which case a trace text file or binary file is obtained froma trace buffer, and the reduction takes place using the trace file asinput.

The trace information, whether obtained statically or dynamically, isrepresented as a tree of events. For example, the tree structure of thepresent invention may reflect the call stacks observed during aprogram's execution. A call stack is represented by one or more nodes inthe tree, and statistics regarding the time spent in the variousroutines and call stacks is stored at each node.

The present invention may be used to present many types of traceinformation in a compact manner which supports performance queries. Forexample, rather than keeping statistics regarding time, tracing may beused to track the number of Java bytecodes executed in each method (i.e.routine) called. The tree structure of the present invention would thencontain statistics regarding bytecodes executed. Tracing may also beused to track memory allocation and deallocation. Every time a routinecreates an object, a trace record could be generated. The tree structureof the present invention would then be used to efficiently store andretrieve information regarding memory allocation.

An advantage of the present invention is that trace information ispresented in a manner which is compact and efficient. Another advantageis that the tree structure of the present invention may be used toquickly and easily answer a variety of performance queries. A furtheradvantage of the present invention is that it allows a system to betraced for long periods of time without losing useful performanceinformation due to a limited buffer space. The use of dynamic tracingand reduction, along with dynamic pruning in some cases, is especiallyuseful in profiling the performance characteristics of long runningprograms. By using dynamic tracing and reduction (and perhaps dynamicpruning), an accurate and informative performance profile may beobtained for a long running program.

BRIEF DESCRIPTION OF THE DRAWINGS

The foregoing and other features and advantages of the present inventionwill become more apparent from the detailed description of the best modefor carrying out the invention as rendered below. In the description tofollow, reference will be made to the accompanying drawings, where likereference numerals are used to identify like parts in the various viewsand in which:

FIG. 1 is an illustration of a portion of a text file trace output;

FIG. 2 is a block diagram of an information handling system capable ofexecuting the performance monitoring and reduction method of the presentinvention;

FIG. 3 is an illustration of a trace sequence, along with arepresentation of the call stack associated with the trace sequence;

FIG. 4 is a pictorial representation of a call stack tree, which may bepresented to a user;

FIG. 5 illustrates another manner in which the call stack tree of FIG. 4may be presented to the user;

FIG. 6 is a flow chart depicting a method for creating a call stack treefrom a trace history file, according to the teachings of the presentinvention;

FIG. 7 is a flow chart depicting a method for creating a call stack treein real time, from a dynamic trace sequence, according to the teachingsof the present invention;

FIG. 8 illustrates several statistics regarding the call stack tree asthey may be presented to the user; and

FIG. 9 illustrates another manner in which call stack tree statisticsmay be presented to the user.

DETAILED DESCRIPTION OF A PREFERRED EMBODIMENT OF THE INVENTION

The invention may be implemented on a variety of hardware platforms,including personal computers, workstations, mini-computers, andmainframe computers. Many of the steps of the method according to thepresent invention may be advantageously implemented on parallelprocessors of various types. Referring now to FIG. 2, a typicalconfiguration of an information handling system that may be used topractice the novel method of the present invention will be described.The computer system of FIG. 2 has at least one processor 10. Processor10 is interconnected via system bus 12 to random access memory (RAM) 16,read only memory (ROM) 14, and input/output (I/O) adapter 18 forconnecting peripheral devices such as disk units 20, tape drives 40, andprinters 42 to bus 12, user interface adapter 22 for connecting keyboard24, mouse 26 having buttons 17a and 17b, speaker 28, microphone 32,and/or other user interface devices such as a touch screen device 29 tobus 12, communication adapter 34 for connecting the information handlingsystem to a data processing network, and display adapter 36 forconnecting bus 12 to display device 38.

Communication adaptor 34 may link the system depicted in FIG. 2 withhundreds or even thousands of similar systems, or other devices, such asremote printers, remote servers, or remote storage units. The systemdepicted in FIG. 2 may be linked to both local area networks (sometimesreferred to as intranets) and wide area networks, such as the Internet.

The present invention is a system, method, and computer readable mediumfor representing program event trace information in a way which is verycompact and efficient, and yet supports a wide variety of queriesregarding system performance. The trace information may be obtained inreal-time, as each event occurs, and be automatically reduced and addedto the trace representation. This type of tracing and reduction isreferred to as dynamic tracing and reduction. Alternately, the trace maybe a trace text file or binary file obtained from a trace buffer, andthe reduction takes place using the trace file as input. This type oftracing and reduction is referred to as static tracing and reduction.

The trace information, whether obtained statically or dynamically, isrepresented as a tree of events. For example, the trace data may berepresented as a tree, where the tree reflects the call stacks observedduring execution. A call stack is an ordered list of routines (i.e.modules, functions, methods, etc.) that have been entered, but not yetexited, at any given moment during the execution of a program. Forexample, if routine A calls routine B, and then routine B calls routineC, while the processor is executing instructions in routine C, the callstack is ABC. When control returns from routine C back to routine B, thecall stack is AB.

FIG. 3 illustrates a portion of a trace sequence, along with the stateof the call stack after each trace event. Note that the trace sequencedepicted in FIG. 3 may be static information contained in a trace textfile. The trace text file is created based on information contained in atrace buffer, and is often created after tracing has been turned off.Alternately, the trace information in FIG. 3 may be dynamicallyobtained. In this case, the information shown in FIG. 3 is acted upon asthe information is obtained, i.e. as each event occurs. Also note thatthe trace sequence depicted in FIG. 3 uses integral time stamps (i.e.time 0, time 1, time 2, etc.). The use of integral time stamps is forillustrative purposes only. The time scale is actually continuous, andevents are not constrained to occurring on integral time boundaries.

Still referring to FIG. 3, note that at time 0, routine C is entered.The call stack at time 0 is thus C. At time 1, routine C calls routineA, and the call stack becomes CA, and so on. The present inventionrepresents the system events, in this case call stacks, in a compact andinformative manner, as depicted in FIG. 4.

Referring now to FIG. 4, an event tree which reflects call stacksobserved during system execution will now be described. At each node inthe tree, several statistics are recorded. In the example shown in FIG.4, the statistics are time-based statistics. The particular statisticsshown include the number of distinct times the call stack is produced,the sum of the time spent in the call stack, the total time spent in thecall stack plus the time in those call stacks invoked from this callstack (referred to as cumulative time), and the number of instances ofthis routine above this instance (indicating depth of recursion).

For example, at node 102 in FIG. 4, the call stack is CAB, and thestatistics kept for this node are 2:3:4:1. Note that call stack CAB isfirst produced at time 2 in FIG. 3, and is exited at time 3. Call stackCAB is produced again at time 4, and is exited at time 7. Thus, thefirst statistic indicates that this particular call stack, CAB, isproduced twice in the trace. The second statistic indicates that callstack CAB exists for three units of time (at time 2, time 4, and time6). The third statistic indicates the cumulative amount of time spent incall stack CAB and those call stacks invoked from call stack CAB (i.e.those call stacks having CAB as a prefix, in this case CABB). Thecumulative time in the example shown in FIG. 4 is four units of time.Finally, the recursion depth of call stack CAB is one, as none of thethree routines present in the call stack have been recursively entered.

Those skilled in the art will appreciate that the tree structuredepicted in FIG. 4 may be implemented in a variety of ways, and avariety of different types of statistics may be maintained at each node.In the described embodiment, each node in the tree contains data andpointers. The data include the name of the routine at that node, and thefour statistics discussed above. Of course, many other types ofstatistical information may be stored at each node. In the describedembodiment, the pointers for each node include a pointer to the node'sparent, a pointer to the first child of the node (i.e. the left-mostchild), a pointer to the next sibling of the node, and a pointer to thenext instance of a given routine in the tree. For example, in FIG. 4,node 104 would contain a parent pointer to node 106, a first childpointer to node 108, a next sibling pointer equal to NULL (note thatnode 104 does not have a next sibling), and a next instance pointer tonode 112. Those skilled in the art will appreciate that other pointersmay be stored to make subsequent analysis more efficient. In addition,other structural elements, such as tables for the properties of aroutine that are invariant across instances (e.g., the routine's name),may also be stored.

The type of performance information and statistics maintained at eachnode are not constrained to time-based performance statistics. Thepresent invention may be used to present many types of trace informationin a compact manner which supports performance queries. For example,rather than keeping statistics regarding time, tracing may be used totrack the number of Java bytecodes executed in each method (i.e.routine) called. The tree structure of the present invention would thencontain statistics regarding bytecodes executed, rather than time. Inparticular, the quantities recorded in the second and third categorieswould reflect the number of bytecodes executed, rather than the amountof time spent in each method.

Tracing may also be used to track memory allocation and deallocation.Every time a routine creates an object, a trace record could begenerated. The tree structure of the present invention would then beused to efficiently store and retrieve information regarding memoryallocation. Each node would represent the number of method calls, theamount of memory allocated within a method, the amount of memoryallocated by methods called by the method, and the number of methodsabove this instance (i.e. the measure of recursion). Those skilled inthe art will appreciate that the tree structure of the present inventionmay be used to represent a variety of performance data in a manner whichis very compact, and allows a wide variety of performance queries to beperformed.

The tree structure shown in FIG. 4 depicts one way in which data may bepictorially presented to a user. The same data may also be presented toa user in tabular form as shown in FIG. 5. Referring now to FIG. 5, acall stack tree presented as a table will now be described. Note thatFIG. 5 contains a routine, pt₋₋ pidtid, which is the main process/threadwhich calls routine C. Table 5 includes columns of data for Level 130,RL 132, Calls 134, Base 136, Cum 138, and Indent 140. Level 130 is thetree level (counting from the root as level 0) of the node. RL 132 isthe recursion level. Calls 134 is the number of occurrences of thisparticular call stack (i.e. the number of times this call stack occurs).Base 136 is the total observed time in the particular call stack. Cum138 is the total time in the particular call stack plus deeper levels.Indent 140 depicts the level of the tree in an indented manner.

Both the pictorial view of the call stack tree, as illustrated in FIG.4, and the tabular view of the call stack tree, as illustrated in FIG.5, may be built dynamically, or built using a trace text file or binaryfile as input. FIG. 6 is a flow chart depicting a method for building acall stack tree using a trace text file as input. In FIG. 6, the callstack tree is being built to illustrate module entry and exit points.

Referring now to FIG. 6, it is first determined if there are more tracerecords in the trace text file (step 150). If so, several pieces of dataare obtained from the trace record, including the time, whether theevent is an enter or a return, and the module name (step 152). Next, thelast time increment is attributed to the current node in the tree (step154). A check is made to determine if the trace record is an enter or anexit record (step 156). If it is an exit record, the tree is traversedto the parent (using the parent pointer), and the current tree node isset equal to the parent node (step 158). If the trace record is an enterrecord, a check is made to determine if the module is already a childnode of the current tree node (step 160). If not, a new node is createdfor the module and it is attached to the tree below the current treenode (step 162). The tree is then traversed to the module's node, andthe current tree node is set equal to the module node (step 164). Thenumber of calls to the current tree node is then incremented (step 166).This process is repeated for each trace record in the trace output file,until there are no more trace records to parse (step 168).

FIG. 7 is a flow chart depicting a method for building a call stack treedynamically, as tracing is taking place during system execution. In FIG.7, as an event is logged, it is added to the tree in real time.Preferably, a call stack tree is maintained for each thread. The callstack tree reflects the call stacks recorded to date, and a current treenode field indicates the current location in a particular tree. When anevent occurs (step 170), the thread ID is obtained (step 171). The time,type of event (i.e. in this case, whether the event is a method entry orexit), the name of the module (i.e. method), location of the thread'scall stack, and location of the thread's "current tree node" are thenobtained (step 172). The last time increment is attributed to thecurrent tree node (step 174). A check is made to determine if the traceevent is an enter or an exit event (step 176). If it is an exit event,the tree is traversed to the parent (using the parent pointer), and thecurrent tree node is set equal to the parent node (step 178). At thispoint, the tree can be dynamically pruned in order to reduce the amountof memory dedicated to its maintenance (step 179). Pruning is discussedin more detail below. If the trace event is an enter event, a check ismade to determine if the module is already a child node of the currenttree node (step 180). If not, a new node is created for the module andit is attached to the tree below the current tree node (step 182). Thetree is then traversed to the module's node, and the current tree nodeis set equal to the module node (step 184). The number of calls to thecurrent tree node is then incremented (step 186). Control is then passedback to the executing module, and the dynamic tracing/reduction programwaits for the next event to occur (step 188).

One of the advantages of using the dynamic tracing/reduction techniquedescribed in FIG. 7 is its enablement of long-term system tracecollection with a finite memory buffer. Very detailed performanceprofiles may be obtained without the expense of an "infinite" tracebuffer. Coupled with dynamic pruning, the method depicted in FIG. 7 cansupport a fixed-buffer-size trace mechanism.

The use of dynamic tracing and reduction (and dynamic pruning in somecases) is especially useful in profiling the performance characteristicsof long running programs. In the case of long running programs, a finitetrace buffer can severely impact the amount of useful trace informationwhich may be collected and analyzed. By using dynamic tracing andreduction (and perhaps dynamic pruning), an accurate and informativeperformance profile may be obtained for a long running program.

Dynamic pruning is not required to use the method of the presentinvention. Many long-running applications reach a type of steady-state,where every possible routine and call stack is present in the tree, andthe dynamic data reduction becomes a matter of walking the tree andupdating statistics. Thus, trace data can be recorded and stored forsuch applications indefinitely within the constraints of a boundedmemory requirement. Pruning has value in reducing the memory requirementfor those situations in which the call stacks are actually unbounded.For example, unbounded call stacks are produced by applications thatload and run other applications.

Pruning can be performed in many ways, and a variety of pruning criteriaare possible. For example, pruning decisions may be based on the amountof cumulative time attributed to a subtree. Note that pruning may bedisabled unless the amount of memory dedicated to maintaining the callstack exceeds some limit. As an exit event is encountered (such as step178 in FIG. 7), the cumulative time associated with the current node iscompared with the cumulative time associated with the parent node. Ifthe ratio of these two cumulative times does not exceed a pruningthreshold (e.g., 0.1), then the current node and all of its descendantsare removed from the tree. The algorithm to build the tree proceeds asbefore by traversing to the parent, and changing the current node to theparent.

Many variations of the above pruning mechanism are possible. Forexample, the pruning threshold can be raised or lowered to regulate thelevel of pruning from very aggressive to none. More global techniquesare also possible, including a periodic sweep of the entire call stacktree, removing all subtrees whose individual cumulative times are not asignificant fraction of their parent node's cumulative times.

The performance data reduction of the present invention allows analysisprograms to easily and quickly answer many questions regarding howcomputing time was spent within the traced program. Examples ofquestions that can be answered using the call stack tree depicted inFIGS. 4 and 5, include questions such as the following:

1. How much time was spent in routine A?

2. How much time was spent in routine A and in routines called, eitherdirectly or indirectly, by A?

3. Of all the time spent in A, how much time was when A was called,either directly or indirectly, by B?

4. Of A's cumulative time, how much was spent in B and routines Bcalled, either directly or indirectly?

5. List all the routines that called A directly, and break out A's timeunder each of them.

6. List all the routines A called directly and apportion A's cumulativetime among them.

Those skilled in the art will appreciate that the answers to the aboveexample questions, and many other questions, may be answered by "walkingthe tree" and accumulating the data stored at various nodes within thecall stack tree.

FIGS. 8 and 9 depict two different types of reports which may beproduced based on the call stack tree depicted in FIGS. 4 and 5. In FIG.8, each routine is listed separately, along with information regardingthe routine. For example, Calls 190 lists the number of times eachroutine has been called. Base 192 is the total time spent in theroutine. Cum 194 is the cumulative time spent in the routine and allroutines called by the routine. Cum2 196 is the cumulative time plustime spent in recursive routines. Ind 198 is an index number generatedto make it easier for an analyst to relate entries in the differentoutput tables. Name 200 is the name of the routine. FIG. 9 depicts muchof the same information shown in FIG. 8, although in a slightlydifferent format.

Although the invention has been described with a certain degree ofparticularity, it should be recognized that elements thereof may bealtered by persons skilled in the art without departing from the spiritand scope of the invention. One of the preferred implementations of theinvention is as sets of instructions resident in the random accessmemory 16 of one or more computer systems configured generally asdescribed in FIG. 2. Until required by the computer system, the set ofinstructions may be stored in another computer readable memory, forexample in a hard disk drive, or in a removable memory such as anoptical disk for eventual use in a CD-ROM drive or a floppy disk foreventual use in a floppy disk drive. Further, the set of instructionscan be stored in the memory of another computer and transmitted over alocal area network or a wide area network, such as the Internet, whendesired by the user. One skilled in the art would appreciate that thephysical storage of the sets of instructions physically changes themedium upon which it is stored electrically, magnetically, or chemicallyso that the medium carries computer readable information. The inventionis limited only by the following claims and their equivalents.

What is claimed is:
 1. A method for monitoring the performance of aprogram, comprising the steps of:obtaining a plurality of trace eventswhich occur as the program executes; representing the trace events asone or more nodes in a tree structure; recording one or more performancestatistics at each node in the tree structure; determining if a selectedevent is represented in the tree structure; and if the selected event isnot represented in the tree structure, adding a new node for theselected event to the tree structure, wherein the new node is a childnode descending from a parent node representing another event.
 2. Amethod according to claim 1, wherein said obtaining step furthercomprises the step of parsing a trace file to obtain one or more traceevents stored in the trace file.
 3. A method according to claim 1,wherein said obtaining step comprises the step of identifying each traceevent in real time as it occurs during execution of the program.
 4. Amethod according to claim 3, wherein said representing step comprisesthe step of adding each trace event to the tree structure in real timeas the trace event occurs.
 5. A method according to claim 4, whereinsaid recording step comprises the step of updating the performancestatistics for each trace event in real time as the trace event occurs.6. A method for monitoring the performance of a program, comprising thesteps of:obtaining a plurality of trace events which occur as theprogram executes; representing the trace events are one or more nodes ina tree structure; and recording one or more performance statistics ateach node in the tree structure, wherein said obtaining step comprisesthe step of identifying one or more call stacks present as the programexecutes, wherein each call stack is an ordered list of one or moreroutines that have been entered during execution of the program.
 7. Amethod according to claim 6, wherein said representing step comprisesthe step of representing each call stack as a set of nodes in a treestructure, wherein each node represents a routine in the call stack. 8.A method according to claim 7, further comprising the stepsof:determining if a selected routine is represented in the treestructure; and if the selected routine is not represented in the treestructure, adding a new node for the selected routine to the treestructure, wherein the new node is a child node descending from a parentnode representing a calling routine.
 9. An information handling system,comprising:a processor; a program which executes on the processor; meansfor obtaining a plurality of trace events which occur as the programexecutes; means for representing the trace events as one or more nodesin a tree structure; and means for recording one or more performancestatistics at each node in the tree structure, wherein said means forobtaining comprises means for identifying one or more call stackspresent as the program executes, wherein each call stack is an orderedlist of one or more routines that have been entered during execution ofthe program.
 10. An information handling system according to claim 9,wherein said means for obtaining further comprises means for parsing atrace file to obtain one or more trace events stored in the trace file.11. An information handling system according to claim 9, wherein saidmeans for obtaining comprises means for identifying each trace event inreal time as it occurs during execution of the program.
 12. Aninformation handling system according to claim 11, wherein said meansfor representing comprises means for adding each trace event to the treestructure in real time as the trace event occurs.
 13. An informationhandling system according to claim 12, wherein said means for recordingcomprises means for updating the performance statistics for each traceevent in real time as the trace event occurs.
 14. An informationhandling system according to claim 9, wherein said means forrepresenting comprises means for representing each call stack as a setof nodes in a tree structure, wherein each node represents a routine inthe call stack.
 15. An information handling system according to claim14, further comprising:means for determining if a selected routine isrepresented in the tree structure; and means for adding a new node forthe selected routine to the tree structure, wherein the new node is achild node descending from a parent node representing a calling routine.16. An information handling system, comprising:a processor; a programwhich executes on the processor; means for obtaining a plurality oftrace events which occur as the program executes; means for representingthe trace events as one or more nodes in a tree structure; means forrecording one or more performance statistics at each node in the treestructure; means for determining if a selected event is represented inthe tree structure; and means for adding a new node for the selectedevent to the tree structure, wherein the new node is a child nodedescending from a parent node representing another event.
 17. A computerreadable medium, comprising:means for obtaining a plurality of traceevents which occur as a program executes; means for representing thetrace events as one or more nodes in a tree structure; means forrecording one or more performance statistics at each node in the treestructure; means for determining if a selected event is represented inthe tree structure; and means for adding a new node for the selectedevent to the tree structure, wherein the new node is a child nodedescending from a parent node representing another event.
 18. A computerreadable medium according to claim 17, wherein said means for obtainingfurther comprises means for parsing a trace file to obtain one or moretrace events stored in the trace file.
 19. A computer readable mediumaccording to claim 17, wherein said means for obtaining comprises meansfor identifying each trace event in real time as it occurs duringexecution of the program.
 20. A computer readable medium according toclaim 19, wherein said means for representing comprises means for addingeach trace event to the tree structure in real time as the trace eventoccurs.
 21. A computer readable medium according to claim 20, whereinsaid means for recording comprises means for updating the performancestatistics for each trace event in real time as the trace event occurs.22. A computer-readable medium, comprising:means for obtaining aplurality of trace events which occur as a program executes; means forrepresenting the trace events as one or more nodes in a tree structure;and means for recording one or more performance statistics at each nodein the tree structure, wherein said means for obtaining comprises meansfor identifying one or more call stacks present as the program executes,wherein each call stack is an ordered list of one or more routines thathave been entered during execution of the program.
 23. A computerreadable medium according to claim 22, wherein said means forrepresenting comprises means for representing each call stack as a setof nodes in a tree structure, wherein each node represents a routine inthe call stack.
 24. A computer readable medium according to claim 23,further comprising:means for determining if a selected routine isrepresented in the tree structure; and means for adding a new node forthe selected routine to the tree structure, wherein the new node is achild node descending from a parent node representing a calling routine.